UniFi Network 9.0: A Game Changer! [YouTube Release]

Additional Resources:

UniFi Blog Post

Connect With Us

Lawrence Systems Shirts and Swag

►👕 Lawrence Systems

AFFILIATES & REFERRAL LINKS

Amazon Affiliate Store
:shopping_cart: Lawrence Systems's Amazon Page

UniFi Affiliate Link
:shopping_cart: Ubiquiti Store

All Of Our Affiliates help us out and can get you discounts!
:shopping_cart: Partners We Love – Lawrence Systems

Gear we use on Kit
:shopping_cart: Kit

Use OfferCode LTSERVICES to get 10% off your order at
:shopping_cart: Tech Supply Direct - Premium Refurbished Servers & Workstations at Unbeatable Prices

Digital Ocean Offer Code
:shopping_cart: DigitalOcean | Cloud Infrastructure for Developers

HostiFi UniFi Cloud Hosting Service
:shopping_cart: HostiFi - Launch UniFi, UISP and Omada in the Cloud

Protect your privacy with a VPN from Private Internet Access
:shopping_cart: https://www.privateinternetaccess.com/pages/buy-vpn/LRNSYS

Patreon
:moneybag: https://www.patreon.com/lawrencesystems

Chapters
00:00 UniFi Network 9.0 - Built to Scale
01:36 UniFi CyberSecure Subscription
03:21 Site Magic Update
04:02 Self Hosted Version 9
04:20 Zone Based Firewall Rules
05:40 UniFi API

1 Like

I’m pretty sure once my 2yr subscription to pfsense+ is up I will be switching to UniFi firewall. They have come a long way and there isn’t much that UniFi can’t do that pfsense can do now days. The firewall rules was a big pain point for me and now that it’s fixed I’ll be moving on.

I am trying the policy based routing again for VPN routing.

The policy list is still top to bottom it seems? Still not able to be edited without complete rewrite.

Also custom DNS settings on the WAN still makes it unusable.

Or I am doing something wrong lol.

I still have my pfsense because of policy based routing is lacking on the UDM pro units. Now that was to be addressed in 9.0 but from looking at it now… its not.

According to this it looks like you can do policy based routing.

Agreed you should be able to. My basic ones like, this network route our this WAN works fine.

But X traffic routed to select domain does not. For example from LAN to cnn.com route over this VPN GW.

I’m not sure what you mean. There is a clear example in the documentation I sent on how to do this.

Examples

Sending Streaming Traffic through a VPN

If you want to send specific streaming traffic from your Apple TV to a VPN Client tunnel, create a Policy Based Route with the following options:

  • Type: Specific Traffic
  • Category: Domain Name
  • Domain Name: Add one or more domains used by the streaming service
  • Target: Apple TV
  • Interface: VPN Client


That’s pretty much what I have, I think. VPN is up also I can ping the GW.

So I just put a new network and made that VPN its default route, its not working so something else might be the issue here.

DNS is not working, IP traffic is… So getting closer.

update:
DNS traffic is working over the VPN network now.

Seems to be a policy based routing issue still.

update
1/15
Looks like you have to make sure that the DNS is AUTO for the vlan/network.
However, no failback rule is not working. It will auto connect to the default internet pending my ticket.

If you had to upgrade today, which device would be you looking at? Prices seem pretty reasonable compared to other products like the Netgate and OPNsense devices.

What else could we do with the NVR drives if we didn’t have a camera system (not allowed to install them at work). That machine does make me rethink what I’m going to do with cameras at home, I’d need a POE switch and some access points to replace the consumer router and the cheezy DVR that came with the cameras.

(going off topic a bit) For cameras at home I was going to get it running with the included DVR, then eventually switch to Frigate and Home Assistant. But with the recent support for third party cameras in the UniFi NVR, this would be SO much easier!

That choice is a bit hard at the moment. I could go with the UXG-Max and manage it with my current on-prem controller. But that feels a bit messy to manage my firewall from a different appliance on an existing network. I would feel like somehow I would block myself out of it lol.

Then on the other hand I am also wanting to setup more cameras and it would be nice to invest in the UDM-Pro-Max for future proofing my setup to be an NVR also. By the end of my thought process I think I would go ahead and spend the money for the UDM-Pro-Max. Then slowly buy unifi cameras because they are kind of pricey. Or if they are able to configure the UP-AI-Port for multiple cameras then I would buy cheaper cameras.

Tom has a video mentioning cameras that have internal detection that are also supported by the latest UniFi NVR software, in theory the cameras I have use internal detection, but it was probably a lie and I won’t know until I try to work with them. Big job that I need to start working on.

Hi All,

With the release of 9.0, is my understanding correct that the opening of the API functionality means that people can now pull more information? Im really hoping for the ability to show total up/down totals per VLAN. Much like “Traffic Totals” on pfSense. Does anyone know of this already existing? Or able to maybe look in to this?